Bjorka

Also known as: Bjorka, bjorka

Bjorka is an underground actor persona that has claimed attacks on victims in a wide range of sectors and geographies. Researchers assess that the Bjorka persona is likely the administrator of a “data leak site” discovered in January 2025, which operates under the moniker “Babuk 2”, ostensibly in reference to the Babuk ransomware that was highly active in the early 2020’s. Researchers also assessed that much of the alleged victim data published on the site was likely recycled from previous information leaks.[Cyjax Bjorka January 29 2025]

Introduction

Bjorka is an underground actor persona that has claimed attacks on victims in a wide range of sectors and geographies. Researchers assess that the Bjorka persona is likely the administrator of a “data leak site” discovered in January 2025, which operates under the moniker “Babuk 2”, ostensibly in reference to the Babuk ransomware that was highly active in the early 2020’s. Researchers also assessed that much of the alleged victim data published on the site was likely recycled from previous information leaks.[Cyjax Bjorka January 29 2025]

Activities and Tactics

Information pending cataloguing.

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • GraphicBooting:
  • Archelaus Beta:

Attribution and Evidence

Information pending cataloguing.

References

[1] [Cyjax Bjorka January 29 2025